• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Failover with vlans and public addresses

Scheduled Pinned Locked Moved HA/CARP/VIPs
5 Posts 2 Posters 2.9k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • R
    rickbaran
    last edited by Nov 22, 2008, 11:52 PM

    I have been trying to do the failover config setup on our network with routed public address on vlans and making progress but I have a couple of questions that I have not been able to find an answer going though the forum and google. Here is what I have done so far.

    I have read the tutorial  [[http://files.pfsense.org/mirror/tutorials/carp/carp-cluster-new.htm[/url] and trying to work thought it using public address and vlans.

    I did the sync net on the 3rd nic on each fw
    I have unique public address on the wans of each fw  xxx.xxx.58.148 and xxx.xxx.58.149
    The sync network is 192.168.168.1/24 on primary and 192.168.168.2/24 on secondary
    The LAN(no vlan) on pri is 192.168.2.175 and sec is 192.168.2.176
    Went though the tutorial listed above I added wan xxx.xxx.58.148, lan 192.168.2.175 and vlan xxx.xxx.53.1 to the VIP(carp) on pri fw. Checked all the boxes shown excluding the “preemption” which doesn’t seem to be in ver 1.2R. Everything that should get synced does.

    Now here is where my questions. All of the vlans have there ip address configured on the vlans the same on each fw. Vlan 5 has xxx.xxx.53.1 on pri and sec fw. Not sure if this correct or not, seems to work but getting errors in the system logs about the secondry mac using the same address.

    Should have a ip conflict and it should not work, correct?

    Am I going to have to have a unique address in the same subnet on the secondary fw vlan? (ex: xxx.xxx.53.2)? These are only /30 so we don’t have an other address to use. Any whay around this?

    I think the biggest thing that is throwing the lack of info that i am finding on the flow of what happenes during the carp failover links to some basic info on this would be good.

    Thanks

    Rick](http://files.pfsense.org/mirror/tutorials/carp/carp-cluster-new.htm)

    1 Reply Last reply Reply Quote 0
    • P
      Perry
      last edited by Nov 23, 2008, 1:11 AM

      Went though the tutorial listed above I added wan xxx.xxx.58.148

      Typo? as you already used it.

      I think the biggest thing that is throwing the lack of info that i am finding on the flow of what happenes during the carp failover links to some basic info on this would be good.

      Will this help?
      http://www.freebsd.org/cgi/man.cgi?query=carp&manpath=FreeBSD+7.0-RELEASE
      http://en.wikipedia.org/wiki/Common_Address_Redundancy_Protocol

      /Perry
      doc.pfsense.org

      1 Reply Last reply Reply Quote 0
      • R
        rickbaran
        last edited by Nov 23, 2008, 3:53 AM

        I read the links and I think that I have it now but just want to make sure. Since the ISP has the route for the xxx.xxx.53.0 network pointing to xxx.xxx.58.148 I assume that this would be the correct way to set this up? Which we don't have enough ip's on each vlan to do this.  :'(

        FW1
        WAN IP xxx.xxx.58.149
        WAN Carp xxx.xxx.58.148
        WAN Gateway xxx.xxx.58.145
        LAN IP192.168.168.254
        LAN Carp 192.168.168.1(gateway for network)
        VLAN1 IP xxx.xxx.53.2
        VLAN1 Carp xxx.xxx.53.1(gateway for network)

        FW2
        WAN IP xxx.xxx.58.150
        LAN IP 192.168.168.253
        VLAN1 IP xxx.xxx.53.3

        1 Reply Last reply Reply Quote 0
        • P
          Perry
          last edited by Nov 23, 2008, 11:12 AM

          I'm not sure why you call them vlans they are wan ip's right?
          Using other in vip might help http://forum.pfsense.org/index.php/topic,7039.0.html

          /Perry
          doc.pfsense.org

          1 Reply Last reply Reply Quote 0
          • R
            rickbaran
            last edited by Nov 23, 2008, 4:33 PM

            No the vlans are vlans. Each of our customers are on their own vlan behind the firewall with public address on their machines. We route through the firewall to the public addresses, no nat or port forwading. Everything in the forum seems to be with nating and port forwarding from the public ip's on the WAN to private ip's.

            This is the current setup that we are trying to cluster.

            WAN Gateway              FW1 WAN              Vlan1 interface          Customers machine
            xxx.xxx.58.145<–-->xxx.xxx.58.148<------->xxx.xxx.53.1<--------->xxx.xxx.53.2

            Thanks

            Rick

            1 Reply Last reply Reply Quote 0
            1 out of 5
            • First post
              1/5
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
              This community forum collects and processes your personal information.
              consent.not_received